StackRadar

CVE-2025-23166

High

Advisory

Published 19 May 2025In the index since 6 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.008
55th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
17
of 17,781 indexed, latest versions
Container images
16
deployed by those charts
Fix available
2 of 3
affected packages

Red Hat Security Advisory: nodejs:20 security update

Carried by container images the latest versions of 17 of 17,781 indexed charts deploy, on 16 images.

Affected packageAffected versionsFixed inImages
nodejsdeb18.13.0+dfsg1-1, 18.19.0+dfsg-6~deb12u1, 18.19.0+dfsg-6~deb12u2, 18.19.1+dfsg-6ubuntu5+6 more18.20.4+dfsg-1~deb12u2, 20.19.2+dfsg-113
nodejsrpm1:20.12.2-2.module+el9.4.0+21731+46b5b8a7, 1:20.16.0-1.module+el9.4.0+22197+9e60f1271:20.19.2-2.module+el9.4.0+23180+d266bac72
nodejs-18apk18.20.8-r9no fix listed1
OSV records
DEBIAN-CVE-2025-23166RHSA-2025:8902UBUNTU-CVE-2025-23166CGA-72rv-6459-558x
Also known as
CGA-f37p-f56r-gcf6

Charts affected

17 by stars
ChartLatestAffected imagesRadar Score
iobrokereugen0.2.61 of 1See more

iobroker eugen 0.2.6

1 of the 1 container images this version deploys carry CVE-2025-23166.

Container imageDigestPackageFixed in
ghcr.io/buanet/iobroker:v9.1.2ca7dc7362968
nodejs@18.20.4-1nodesource1
18.20.4+dfsg-1~deb12u2

Open the chart page →

11,458
difykubeblocksVerified publisher0.5.11 of 5See more

dify kubeblocks 0.5.1

1 of the 5 container images this version deploys carry CVE-2025-23166.

Container imageDigestPackageFixed in
langgenius/dify-api:0.6.11fca918260dd6
nodejs@18.19.0+dfsg-6~deb12u1
18.20.4+dfsg-1~deb12u2

Open the chart page →

20,403
vaultwarden-kubernetes-secretsvaultwarden-kubernetes-secrets0.0.0-main1 of 2See more

vaultwarden-kubernetes-secrets vaultwarden-kubernetes-secrets 0.0.0-main

1 of the 2 container images this version deploys carry CVE-2025-23166.

Container imageDigestPackageFixed in
ghcr.io/antoniolago/vaultwarden-kubernetes-secrets:0.0.0-main13e267ad7d94
nodejs@20.20.0-1nodesource1
no fix listed

Open the chart page →

4,010
node-appbryopsida0.5.11 of 2See more

node-app bryopsida 0.5.1

1 of the 2 container images this version deploys carry CVE-2025-23166.

Container imageDigestPackageFixed in
ghcr.io/bryopsida/k8s-dev-pod:main82d0b161161d
nodejs@22.16.0-1nodesource1
no fix listed

Open the chart page →

14,352
arbitrumchronicleVerified publisher0.3.41 of 1See more

arbitrum chronicle 0.3.4

1 of the 1 container images this version deploys carry CVE-2025-23166.

Container imageDigestPackageFixed in
offchainlabs/nitro-node:v3.7.6-c0fe95e9f779fa84b7b
nodejs@18.20.4+dfsg-1~deb12u1
18.20.4+dfsg-1~deb12u2

Open the chart page →

6,998
codehubcodehubVerified publisher6.2.181 of 5See more

codehub codehub 6.2.18

1 of the 5 container images this version deploys carry CVE-2025-23166.

Container imageDigestPackageFixed in
jupyterhub/jupyterhub:5.4.63974ba945e65
nodejs@18.19.1+dfsg-6ubuntu5
no fix listed

Open the chart page →

13,220
difydify1.0.01 of 4See more

dify dify 1.0.0

1 of the 4 container images this version deploys carry CVE-2025-23166.

Container imageDigestPackageFixed in
langgenius/dify-api:1.0.0066035f93856
nodejs@18.19.0+dfsg-6~deb12u2
18.20.4+dfsg-1~deb12u2

Open the chart page →

19,224
dominodomino-iisasVerified publisher0.3.11 of 3See more

domino domino-iisas 0.3.1

1 of the 3 container images this version deploys carry CVE-2025-23166.

Container imageDigestPackageFixed in
ghcr.io/iisas/domino-frontend:k8s8e53861be292
nodejs@18.20.4+dfsg-1~deb12u1
18.20.4+dfsg-1~deb12u2

Open the chart page →

10,270
arbitrumdysnixVerified publisher0.1.11 of 1See more

arbitrum dysnix 0.1.1

1 of the 1 container images this version deploys carry CVE-2025-23166.

Container imageDigestPackageFixed in
offchainlabs/nitro-node:v3.1.0-7d1d84ce95865866129
nodejs@18.19.0+dfsg-6~deb12u2
18.20.4+dfsg-1~deb12u2

Open the chart page →

9,244
scanservjsgabe565Verified publisher0.9.21 of 1See more

scanservjs gabe565 0.9.2

1 of the 1 container images this version deploys carry CVE-2025-23166.

Container imageDigestPackageFixed in
sbs20/scanservjs:release-v3.0.3dad1fd6e9a98
nodejs@18.13.0+dfsg1-1
18.20.4+dfsg-1~deb12u2

Open the chart page →

13,241
deconzjanip81-helm-chartsVerified publisher0.1.11 of 1See more

deconz janip81-helm-charts 0.1.1

1 of the 1 container images this version deploys carry CVE-2025-23166.

Container imageDigestPackageFixed in
deconzcommunity/deconz:2.29.2062de2362641
nodejs@18.19.0+dfsg-6~deb12u2
18.20.4+dfsg-1~deb12u2

Open the chart page →

10,780
k8s-dev-podk8s-dev-pod0.3.11 of 1See more

k8s-dev-pod k8s-dev-pod 0.3.1

1 of the 1 container images this version deploys carry CVE-2025-23166.

Container imageDigestPackageFixed in
ghcr.io/bryopsida/k8s-dev-pod:main82d0b161161d
nodejs@22.16.0-1nodesource1
no fix listed

Open the chart page →

8,811
kubiya-runnerkubiya-helm-chartsOfficialVerified publisher0.9.41 of 9See more

kubiya-runner kubiya-helm-charts 0.9.4

1 of the 9 container images this version deploys carry CVE-2025-23166.

Container imageDigestPackageFixed in
ghcr.io/kubiyabot/agent-manager:v0.4.13757bdd779345
nodejs@18.20.8-1nodesource1
20.19.2+dfsg-1

Open the chart page →

20,204
chatbot-ai-sampleopenshift0.1.62 of 4See more

chatbot-ai-sample openshift 0.1.6

2 of the 4 container images this version deploys carry CVE-2025-23166.

Container imageDigestPackageFixed in
quay.io/ai-lab/llamacpp_python:latest70d138997acd
nodejs@1:20.16.0-1.module+el9.4.0+22197+9e60f127
1:20.19.2-2.module+el9.4.0+23180+d266bac7
quay.io/redhat-ai-dev/chatbot:latest59fe607dfdf2
nodejs@1:20.12.2-2.module+el9.4.0+21731+46b5b8a7
1:20.19.2-2.module+el9.4.0+23180+d266bac7

Open the chart page →

18,922
coolifyquench-coolifyVerified publisher0.0.171 of 4See more

coolify quench-coolify 0.0.17

1 of the 4 container images this version deploys carry CVE-2025-23166.

Container imageDigestPackageFixed in
ghcr.io/quenchworks/images/coolify-realtimedigest-pinnedf128e512c9c0
nodejs-18@18.20.8-r9
no fix listed

Open the chart page →

433
coolify-realtimequench-coolify-realtimeVerified publisher0.0.71 of 1See more

coolify-realtime quench-coolify-realtime 0.0.7

1 of the 1 container images this version deploys carry CVE-2025-23166.

Container imageDigestPackageFixed in
ghcr.io/quenchworks/images/coolify-realtimedigest-pinnedf128e512c9c0
nodejs-18@18.20.8-r9
no fix listed

Open the chart page →

306
the0the0Verified publisher0.9.81 of 9See more

the0 the0 0.9.8

1 of the 9 container images this version deploys carry CVE-2025-23166.

Container imageDigestPackageFixed in
ghcr.io/alexanderwanyoike/the0/runtime:1.14.7459010a02aff
nodejs@20.20.2-1nodesource1
no fix listed

Open the chart page →

7,248

Container images carrying it

16 by charts deploying them

A fixed version is listed for 2 of the 3 affected packages.

Container imageDigestPackageFixed inUsed by
ghcr.io/bryopsida/k8s-dev-pod:main82d0b161161d
nodejs@22.16.0-1nodesource1
no fix listed
2
ghcr.io/quenchworks/images/coolify-realtimef128e512c9c0
nodejs-18@18.20.8-r9
no fix listed
2
deconzcommunity/deconz:2.29.2062de2362641
nodejs@18.19.0+dfsg-6~deb12u2
18.20.4+dfsg-1~deb12u2
1
jupyterhub/jupyterhub:5.4.63974ba945e65
nodejs@18.19.1+dfsg-6ubuntu5
no fix listed
1
langgenius/dify-api:1.0.0066035f93856
nodejs@18.19.0+dfsg-6~deb12u2
18.20.4+dfsg-1~deb12u2
1
langgenius/dify-api:0.6.11fca918260dd6
nodejs@18.19.0+dfsg-6~deb12u1
18.20.4+dfsg-1~deb12u2
1
offchainlabs/nitro-node:v3.7.6-c0fe95e9f779fa84b7b
nodejs@18.20.4+dfsg-1~deb12u1
18.20.4+dfsg-1~deb12u2
1
offchainlabs/nitro-node:v3.1.0-7d1d84ce95865866129
nodejs@18.19.0+dfsg-6~deb12u2
18.20.4+dfsg-1~deb12u2
1
sbs20/scanservjs:release-v3.0.3dad1fd6e9a98
nodejs@18.13.0+dfsg1-1
18.20.4+dfsg-1~deb12u2
1
ghcr.io/alexanderwanyoike/the0/runtime:1.14.7459010a02aff
nodejs@20.20.2-1nodesource1
no fix listed
1
ghcr.io/antoniolago/vaultwarden-kubernetes-secrets:0.0.0-main13e267ad7d94
nodejs@20.20.0-1nodesource1
no fix listed
1
ghcr.io/buanet/iobroker:v9.1.2ca7dc7362968
nodejs@18.20.4-1nodesource1
18.20.4+dfsg-1~deb12u2
1
ghcr.io/iisas/domino-frontend:k8s8e53861be292
nodejs@18.20.4+dfsg-1~deb12u1
18.20.4+dfsg-1~deb12u2
1
ghcr.io/kubiyabot/agent-manager:v0.4.13757bdd779345
nodejs@18.20.8-1nodesource1
20.19.2+dfsg-1
1
quay.io/ai-lab/llamacpp_python:latest70d138997acd
nodejs@1:20.16.0-1.module+el9.4.0+22197+9e60f127
1:20.19.2-2.module+el9.4.0+23180+d266bac7
1
quay.io/redhat-ai-dev/chatbot:latest59fe607dfdf2
nodejs@1:20.12.2-2.module+el9.4.0+21731+46b5b8a7
1:20.19.2-2.module+el9.4.0+23180+d266bac7
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.